<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; windows 7</title>
	<atom:link href="http://blog.fortinet.com/tag/windows-7/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Wed, 08 Sep 2010 16:35:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>jleggio@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>jleggio@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>jleggio@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Win7 remote DoS publicly disclosed</title>
		<link>http://blog.fortinet.com/win7-remote-dos-publicly-disclosed/</link>
		<comments>http://blog.fortinet.com/win7-remote-dos-publicly-disclosed/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 14:53:10 +0000</pubDate>
		<dc:creator>DMaciejak</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[laurent gaffie]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=722</guid>
		<description><![CDATA[Laurent Gaffié disclosed on Nov. 11 on his blog a proof of concept written in Python. This occured just the morrow after the Black Tuesday, and seems the author does not follow responsible disclosure, and decided to publicly disclosed the code, as he disagreed with Microsoft&#8217;s answer (they wanted to delay the patch in a [...]]]></description>
			<content:encoded><![CDATA[<p>Laurent Gaffié disclosed on Nov. 11 on <a id="misk" title="his blog" href="http://g-laurent.blogspot.com/2009/11/windows-7-server-2008r2-remote-kernel.html">his blog</a> a proof of concept written in Python. This occured just the morrow after the Black Tuesday, and seems the author does not follow responsible disclosure, and decided to publicly disclosed the code, as he disagreed with Microsoft&#8217;s answer (they wanted to delay the patch in a service pack rather than a Black Tuesday patch).</p>
<p>This piece of code (see Figure 1) has been verified to successfully remotely crash Microsoft Windows 7 and Windows 2008-R2. It is caused by sending a specially crafted NetBIOS header wrongly specifying the SMB (Server Message Block) packet size. No error messages dialog box nor evidence of the bug is recorded in the event logs, the computer just freezes.</p>
<p><img class="alignnone size-full wp-image-721" title="win7code" src="http://blog.fortinet.com/wp-content/uploads/2009/11/win7code.jpg" alt="win7code" /><em><br />
Figure 1: code extract</em><br />
Moreover, the issue occurs in pre-authentication stage so no credential is needed.</p>
<p>To trigger this issue, the victim must be trapped to open a Windows share, so just a link of type <em>file://ip/something</em> on an HTML page could do the trick. As of writing, no CVE number has been associated to this issue, however thanks to our IPS decoder signature, Fortinet customers are proactively protected with ¨<a id="g:as" title="NBSS.Invalid.Fragment" href="http://www.fortinet.com/ids/AID110034945">NBSS.Invalid.Fragment</a>¨ detection.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/win7-remote-dos-publicly-disclosed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
